Microsoft Certified: Azure Developer Associate (AZ-204) practice questions
228 free questions with answers and explanations.
- 151.A company is developing an Azure Function App that needs to connect to an SFTP server hosted on a virtual machine within an Azure Virtual Network (VNet). The SFTP server is only accessible from within the VNet. The Azure Function App is deployed to a Consumption Plan. Which networking configuration is required to enable the Azure Function App to securely connect to the SFTP server while maintaining the serverless benefits of the Consumption Plan?Implement Azure security
- 152.A developer is building a multi-tenant SaaS application on Azure. The application's backend consists of Azure Functions and Azure App Services. Users from different Azure Active Directory (AAD) tenants will access the application. The application needs to authenticate users and then authorize their access to specific resources based on their tenant and assigned roles within that tenant. The application itself is registered in the developer's AAD tenant. Which authentication and authorization flow should the developer implement to allow users from other AAD tenants to securely sign in and access the application?Implement Azure security
- 153.A developer is building an Azure Function App that needs to securely access secrets stored in Azure Key Vault. The Function App is deployed to an Azure App Service Plan. The developer wants to avoid hardcoding credentials and ensure that the Function App can authenticate to Key Vault automatically using its own identity. Which authentication method should the developer implement?Implement Azure security
- 154.A company is developing a highly sensitive document processing application using Azure Kubernetes Service (AKS). The application processes confidential financial data, and regulatory compliance requires that all data at rest, including data stored in persistent volumes mounted to AKS pods, must be encrypted with customer-managed keys (CMK) from Azure Key Vault. Which solution should the developer implement to ensure that AKS persistent volumes are encrypted with CMK?Implement Azure security
- 155.A software development company is building a new multi-tenant SaaS application on Azure. The application's backend consists of several Azure API Management (APIM) instances that expose APIs to various client applications. Each client application belongs to a different tenant in Azure Active Directory (AAD) and needs to access the APIM APIs using its own identity. The solution must ensure that APIM can securely validate incoming access tokens issued by AAD for any tenant, without explicitly configuring each tenant's details in APIM. Which APIM policy configuration will allow this behavior?Implement Azure security
- 156.A company is developing a microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely access specific Azure resources (e.g., Azure Storage, Azure Key Vault) without sharing credentials or using a single, highly privileged identity for the entire cluster. The security team mandates that each pod should have its own distinct identity for authentication. Which AKS feature should the developer leverage?Implement Azure security
- 157.A company is developing a new web application that will be hosted on Azure App Service. The application needs to securely store and retrieve secrets from Azure Key Vault. The security policy dictates that the application should not manage any credentials (like client IDs or client secrets) for authenticating to Key Vault. Which authentication mechanism should the developer configure for the App Service to access Azure Key Vault?Implement Azure security
- 158.A developer is implementing a new Azure App Service web application that needs to store sensitive configuration data, such as database connection strings and API keys. This data must be kept outside of the application's source code and configuration files. The solution must provide strong encryption for data at rest and allow for granular access control. Which Azure service is the most appropriate for securely storing and managing these secrets?Implement Azure security
- 159.A company is developing a new microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely call other internal microservices within the AKS cluster, and also external Azure services like Azure Key Vault and Azure Cosmos DB. The security team insists on using a zero-trust model, meaning every service call must be explicitly authenticated and authorized. Which solution provides the most robust and scalable way to enforce identity-based access control between microservices within AKS and to external Azure services?Implement Azure security
- 160.A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely access Azure resources (e.g., Azure Key Vault, Azure Storage) using its own distinct identity, without embedding secrets directly into the pod configurations or using a single shared identity for all microservices. The solution must ensure that the identity is automatically provisioned and rotated by Azure. Which authentication mechanism should the team implement?Implement Azure security
- 161.A developer is building an Azure Function App that processes sensitive customer data. The Function App needs to connect to an SFTP server hosted on-premises within the corporate network. The corporate network has strict firewall rules and only allows outbound connections from specific IP ranges. Which networking feature should be configured for the Azure Function App to enable secure and controlled access to the on-premises SFTP server?Implement Azure security
- 162.A healthcare company is developing an Azure Function App that processes patient health information (PHI). The Function App needs to store configuration settings, including connection strings to a highly secured database, in a secure manner. These settings must be accessible by the Function App but should never be exposed in plain text in source control or application settings. An additional requirement is that the settings should be automatically rotated every 90 days. Which Azure service should be used to store and manage these configuration settings?Implement Azure security
- 163.A developer is creating an Azure Function App that needs to send sensitive notifications to an Azure Service Bus topic. The security team has mandated that the Function App should only have the minimum necessary permissions to publish messages to the topic and nothing more. Which Azure RBAC role should be assigned to the Azure Function App's managed identity to meet this requirement?Implement Azure security
- 164.A financial institution is developing a new serverless application using Azure Functions. This application will process sensitive customer financial data and must comply with stringent regulatory requirements for data encryption at rest. Specifically, the institution requires that encryption keys for the Azure Storage Account used by the Function App are managed by the institution itself, not by Microsoft. Which Azure security feature should be implemented to meet this requirement?Implement Azure security
- 165.A company is developing a microservices-based application using Azure Kubernetes Service (AKS). Each microservice needs to securely access specific secrets stored in Azure Key Vault. The solution must ensure that only authorized microservices can retrieve their respective secrets. Which approach should be implemented?Implement Azure security
- 166.A company is developing a new API that will be consumed by several client applications. The API needs to restrict access based on the calling application's identity, not the end-user's identity. Which type of Azure Active Directory application permission should be used when registering the API and its client applications?Implement Azure security
- 167.A company is developing an Azure Function App that needs to send sensitive notifications to a queue in Azure Service Bus. The security team has mandated that the Function App should only have the minimum necessary permissions to send messages to this specific queue and no other operations (e.g., receiving, managing). Which Azure Service Bus data role should be assigned to the Function App's managed identity?Implement Azure security
- 168.A company is developing a new microservices application using Azure Kubernetes Service (AKS). The application consists of several microservices that communicate with each other. The security team mandates a zero-trust network policy, meaning that no microservice should implicitly trust another, and all inter-service communication must be authenticated and authorized. Which security pattern should be implemented to enforce this zero-trust communication within the AKS cluster?Implement Azure security
- 169.A company is migrating an existing web application to Azure App Service. The application uses a custom authentication system that validates user credentials against an on-premises Active Directory. The company wants to integrate this application with Azure Active Directory (AAD) to leverage AAD's security features, but users must continue to authenticate primarily against the on-premises Active Directory without syncing password hashes to the cloud. Which Azure AD authentication method should be used to meet these requirements?Implement Azure security
- 170.A financial services company is developing a highly sensitive document management system using Azure Blob Storage. Compliance regulations require that all data at rest in the storage account must be encrypted using encryption keys that are managed and controlled solely by the customer, not by Microsoft. This includes the ability to revoke access to the keys at any time. Which encryption solution should be implemented for the Azure Storage account?Implement Azure security
- 171.A company is migrating an existing on-premises web application to Azure App Service. The application uses Windows Integrated Authentication (WIA) and requires users to authenticate against their on-premises Active Directory. The company wants to maintain the single sign-on experience for users without synchronizing password hashes to Azure AD or deploying AD FS. Which Azure AD authentication method is appropriate for this scenario?Implement Azure security
- 172.A developer is building an ASP.NET Core web application hosted on Azure App Service. The application needs to authenticate users from a multi-tenant Azure Active Directory (AAD) tenant. Which authentication flow is most suitable for this scenario, allowing users to sign in without providing their credentials to the application directly?Implement Azure security
- 173.A company is developing a new serverless application using Azure Functions. The application will process sensitive customer data and store it in Azure Cosmos DB. Security requirements mandate that all communication between the Azure Function and Cosmos DB must be encrypted end-to-end, and the Function must connect to Cosmos DB without exposing its network traffic to the public internet. Which Azure networking feature should be used to meet these requirements?Implement Azure security
- 174.A company is developing an Azure Function that processes orders. The function needs to connect to an Azure SQL Database. To ensure the connection is secure and uses the principle of least privilege, which connection string component should be avoided, and what is the best practice for secure access?Implement Azure security
- 175.A developer is creating an Azure Function that needs to interact with an Azure Storage Account. To enhance security, the function should authenticate to the storage account using a managed identity. Which type of managed identity should the developer use if the function app is already deployed and needs to share the identity with other Azure resources?Implement Azure security
- 176.A company is developing an Azure API Management (APIM) instance that exposes several backend APIs. These backend APIs are hosted on Azure App Services and are secured using Azure Active Directory authentication. The APIM instance needs to authenticate to the backend APIs using its own identity, without exposing any credentials to the APIM policy. Which mechanism should the developer use to enable APIM to securely authenticate to the backend App Services?Implement Azure security
- 177.A global e-commerce company uses an Azure App Service web application to handle customer orders. During peak sales events, traffic can surge dramatically, requiring the application to scale out rapidly to hundreds of instances. The company needs to ensure that the application can handle these sudden spikes in demand without manual intervention and then scale back down to minimize costs during off-peak hours. Which Azure App Service scaling feature is MOST suitable for this requirement?Develop Azure compute solutions
- 178.A company is developing a new serverless application that processes incoming sensor data from IoT devices. The application needs to execute small, event-driven functions in response to data ingestion, with minimal operational overhead. The solution must automatically scale based on the volume of incoming data and only incur costs when functions are actively running. Which Azure compute solution is most appropriate for this scenario?Develop Azure compute solutions
- 179.A company is deploying a new web application that needs to handle intermittent, unpredictable traffic spikes. The application is built using .NET Core and is containerized. It needs to scale down to zero instances when idle to minimize costs, and then scale up rapidly to handle incoming requests. Which Azure compute solution is BEST suited for this scenario?Develop Azure compute solutions
- 180.An existing application is composed of several independent components that are currently running on separate physical servers. The company wants to migrate these components to Azure, maintaining isolation between them but consolidating them onto shared infrastructure to reduce costs. Each component requires a specific operating system configuration and runtime environment that cannot be easily containerized. The company needs to manage dependencies and updates for each component independently. Which Azure compute solution is the most appropriate?Develop Azure compute solutions
- 181.A development team is deploying a new web application to Azure. The application consists of several microservices, each packaged as a Docker container. The team requires a fully managed service that can orchestrate these containers, provide automatic scaling, and handle service discovery without requiring them to manage the underlying virtual machines. Which Azure compute solution is BEST suited for this scenario?Develop Azure compute solutions
- 182.A logistics company uses an Azure App Service web application to track shipments. During peak hours, the application experiences slow response times due to increased user traffic. The company wants to ensure consistent performance during these spikes without over-provisioning resources during off-peak hours. Which App Service feature should be configured to address this requirement efficiently?Develop Azure compute solutions
- 183.A data analytics company uses Azure Functions to process incoming telemetry data from IoT devices. The data arrives in batches and each batch needs to be processed within 5 minutes. However, some processing tasks can occasionally take up to 7 minutes due to large data volumes or external service delays. The function is configured with a default timeout. What is the MINIMUM timeout setting (in minutes) required for the Azure Function to ensure all batches are processed successfully without premature termination, assuming the function needs to handle the occasional 7-minute processing time?Develop Azure compute solutions
- 184.A company is modernizing its on-premises data processing workflows by migrating them to Azure. The workflows involve running a series of complex, long-running computational tasks that can be broken down into many independent sub-tasks. These sub-tasks need to be executed in parallel across a pool of compute nodes, and the company requires a managed service that can automatically provision and scale these nodes, distribute tasks, and handle task failures. Which Azure compute solution is BEST suited for this scenario?Develop Azure compute solutions
- 185.A company is designing a system to process large volumes of sensor data. The data arrives continuously and needs to be processed in real-time by a series of stateless microservices. These microservices are containerized and need to scale dynamically based on the incoming data volume, potentially processing millions of events per second. The company wants a fully managed solution that abstracts away server infrastructure and provides advanced routing and traffic management capabilities. Which Azure compute solution is best suited for this?Develop Azure compute solutions
- 186.A company is developing a new serverless application that processes incoming telemetry data from IoT devices. The application needs to execute small, event-driven code snippets in response to data arrival, scale automatically based on demand, and incur costs only when the code is actively running. Which Azure compute solution is BEST suited for this scenario?Develop Azure compute solutions
- 187.A financial institution is deploying a new service to Azure Kubernetes Service (AKS). The service requires persistent storage that can be accessed concurrently by multiple pods across different nodes within the AKS cluster. The storage solution must also support read-write access from multiple pods simultaneously. Which Azure storage solution is MOST appropriate for this requirement?Develop Azure compute solutions
- 188.A developer is configuring an Azure Function with an HTTP trigger. The function needs to accept JSON payloads up to 10 MB in size. The default timeout for HTTP-triggered functions in a Consumption plan is 5 minutes. The processing logic for some payloads might take up to 7 minutes due to complex calculations. Which configuration change is MOST critical to ensure the function completes successfully?Develop Azure compute solutions
- 189.A company is deploying a new containerized application to Azure Kubernetes Service (AKS). The application requires persistent storage that can be shared across multiple pods and dynamically provisioned as needed. The storage solution must be highly available and resilient to node failures. Which type of Azure storage should be used for this requirement?Develop Azure compute solutions
- 190.A company is redesigning its backend infrastructure to use a message-driven architecture. They are using Azure Service Bus queues for reliable message delivery. A critical requirement is to prevent poison messages from indefinitely blocking the queue or being repeatedly processed, which could lead to resource exhaustion or data corruption. What Azure Service Bus feature should be configured to handle these problematic messages effectively?Develop Azure compute solutions
- 191.A company is deploying a new web application that requires a highly scalable and fault-tolerant backend. The application processes user-uploaded images, which are then stored in Azure Blob Storage. The image processing is a CPU-intensive task and can take varying amounts of time. The company wants to minimize operational overhead and only pay for compute resources when the processing is actively running. Which Azure compute solution is most appropriate for the image processing workload?Develop Azure compute solutions
- 192.A media company uses Azure Container Instances (ACI) to run a series of short-lived, burstable containerized tasks for video transcoding. Each task processes a segment of a video, and the number of tasks varies significantly throughout the day. The company wants to optimize costs by only paying for the exact compute resources consumed during the container's execution, without managing any underlying virtual machines or orchestration. Which ACI billing model is most relevant for this scenario?Develop Azure compute solutions
- 193.A manufacturing company uses an Azure App Service web application to display real-time production line data. During peak shifts, the application experiences high load, and it must scale out to ensure responsiveness. During off-peak hours, the application should scale in to reduce costs. The company wants to implement a robust autoscaling solution that adjusts the number of instances based on the average CPU utilization of the existing instances. What is the PRIMARY metric that should be configured for the autoscaling rule?Develop Azure compute solutions
- 194.A company is developing an Azure Function that needs to periodically fetch data from an external API, transform it, and store it in Azure Cosmos DB. The function should run automatically every hour without requiring any explicit HTTP requests. Which trigger type is most suitable for this Azure Function?Develop Azure compute solutions
- 195.A manufacturing company uses an Azure App Service web application to display real-time production metrics. During peak shifts, the application experiences high load, requiring increased compute capacity. The company wants to automatically adjust the number of instances based on CPU utilization to ensure responsiveness and optimize costs. Which App Service feature should be configured?Develop Azure compute solutions
- 196.A developer needs to deploy a legacy ASP.NET web application to Azure. The application requires specific older versions of .NET Framework components and has some dependencies on Windows-specific features. The company wants to migrate this application with minimal code changes while ensuring high availability and scalability. Which Azure compute solution should the developer choose?Develop Azure compute solutions
- 197.A software company is developing a new cloud-native application that needs to run containerized microservices. The application experiences unpredictable traffic patterns with frequent scaling to zero during idle periods to minimize costs. The team wants to avoid managing Kubernetes clusters directly but requires advanced traffic management capabilities, such as traffic splitting for A/B testing and revision management for safe deployments. Which Azure compute solution is the MOST suitable for this scenario?Develop Azure compute solutions
- 198.A developer is creating an Azure Function that needs to access a secret (e.g., a database connection string) securely. The secret should not be hardcoded in the application code or stored directly in the Function App settings. The solution must follow best practices for secret management and integrate seamlessly with the Azure Function environment. Which Azure service should be used to store and retrieve the secret?Develop Azure compute solutions
- 199.A company is developing a new application that will process a high volume of messages from an Azure Service Bus queue. The processing involves complex business logic, and each message must be processed reliably, even if there are transient errors. The application needs to be able to scale out automatically based on the queue length and process messages concurrently. Which Azure Functions trigger and hosting plan combination is MOST appropriate for this scenario?Develop Azure compute solutions
- 200.A development team is building a new microservices application that will run in Azure. Each microservice is packaged as a Docker container. The team needs a solution that allows them to quickly deploy and run individual containers without managing underlying virtual machines or a full Kubernetes cluster. The solution should also provide per-second billing and be suitable for burstable, short-lived workloads. Which Azure compute service should they choose?Develop Azure compute solutions